Description
A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
Published: 2026-10-01
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A flaw in the rubygem-katello component permits a missing return statement after an unauthorized error to allow the request flow to continue into downstream business logic and database validation. This bypass lets an attacker glean the existence of Users, Organizations, and Products through differential HTTP responses, exposing internal state. The vulnerability does not grant direct code execution but enables critical information disclosure that can aid in further attacks.

Affected Systems

Red Hat Satellite 6 and Red Hat Satellite 6.19 for RHEL 9 are affected when they run the vulnerable rubygem-katello package. The issue applies to all nodes that expose the RegistryProxiesController endpoints, including Satellite Capsules and satellite utilities components tied to those versions.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, suggesting limited but possible exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation to date. The likely attack vector is remote, through crafted HTTP requests sent to the RegistryProxiesController endpoints. Detection may involve monitoring for repeated enumeration requests or unusual API traffic.

Generated by OpenCVE AI on October 1, 2026 at 19:28 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Apply the Red Hat Security Advisory RHSA-2026:74503 to upgrade the rubygem-katello package to the fixed version.
  • Restart Satellite services to activate the updated package on all nodes.
  • If a patch cannot be applied immediately, isolate or block external access to the RegistryProxiesController endpoints using firewalls or network segmentation to prevent enumeration attempts.

Generated by OpenCVE AI on October 1, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
Title Rubygem-katello: improper authorization logic allows resource enumeration
First Time appeared Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
Weaknesses CWE-203
CPEs cpe:/a:redhat:satellite:6
cpe:/a:redhat:satellite:6.19::el9
cpe:/a:redhat:satellite_capsule:6.19::el9
cpe:/a:redhat:satellite_utils:6.19::el9
Vendors & Products Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Redhat Satellite Satellite Capsule Satellite Utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T18:02:58.311Z

Reserved: 2026-06-18T19:08:09.850Z

Link: CVE-2026-56098

cve-icon Vulnrichment

Updated: 2026-10-01T18:02:54.860Z

cve-icon NVD

Status : Received

Published: 2026-10-01T18:17:19.763

Modified: 2026-10-01T19:17:23.160

Link: CVE-2026-56098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:30:11Z

Weaknesses